Redeemer Ransomware (.redeem)
#1
Redeemer Ransomware (.redeem) (2025. 01. 17. 456)
 
AppCheck Anti-Ransomware : Redeemer Ransomware (.redeem) Block Video


Distribution Method : Unknown
 
MD5 : e37a0ece30267233f1dddf3c2300393f
 
Major Detection Name : Ransom:Win32/Redeemer.MK!MTB (Microsoft), Ransom.Win32.REDEEM.YXBLV (Trend Micro)
 
Encrypted File Pattern : .redeem
 
Malicious File Creation Location :
 
  • C:\Windows\ProgramData
  • C:\Windows\ProgramData\calc.exe
  • C:\Windows\SQL
  • C:\Windows\SQL\taskhost.exe
  • C:\Windows\SQL\rem.bat
  • C:\Windows\svchost
  • C:\Windows\svchost\conhost.exe


Payment Instruction File : Read Me.TXT
 
Major Characteristics :
 
  • Offline Encryption
  • Disable system restore (vssadmin delete shadows /All /Quiet)
  • Deletes event log (wevtutil clear-log Application, wevtutil clear-log Security, wevtutil clear-log Setup, wevtutil clear-log System)


More Info HERE

Content lifted from CheckMAL site with permission
[-] The following 1 user says Thank You to jasonX for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
K-Lite Codec Pack 19.6.0 / 19.6.1 Update
Changes in 19.6.0:...harlan4096 — 11:42
Free Download Manager 6.33.2.6656
Changes in 6.33.2....harlan4096 — 11:41
Vivaldi 7.9 Build 3970.45
Vivaldi 7.9 Build ...harlan4096 — 11:40
Apples Releases the 26.4 Versions of iOS...
Apple has just rel...harlan4096 — 11:38
Opera 129.0.5823.22
Hello! Opera st...harlan4096 — 11:37

[-]
Birthdays
Today's Birthdays
avatar (44)gapedDow
avatar (38)snorydar
Upcoming Birthdays
avatar (46)qaqapeti

[-]
Online Staff
There are no staff members currently online.

>